{"id":"CVE-2020-25694","year":2020,"sequence":25694,"component":"client","score":8.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","first_published":"2020-11-12","source_url":"https://www.postgresql.org/support/security/CVE-2020-25694/","facts":{"affected":{"10":"10","11":"11","12":"12","13":"13","9.5":"9.5","9.6":"9.6"},"component":"client","cvss_version":"3.0","description_en":"Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission.\n\nAffected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter.\n\nThis also fixes how the \\connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used.\n\nThe PostgreSQL project thanks Peter Eisentraut for reporting this problem.","first_published":"2020-11-12","fixed":{"10":"10.15","11":"11.10","12":"12.5","13":"13.1","9.5":"9.5.24","9.6":"9.6.20"},"id":"CVE-2020-25694","introduced":{},"published":{"10":"2020-11-12","11":"2020-11-12","12":"2020-11-12","13":"2020-11-12","9.5":"2020-11-12","9.6":"2020-11-12"},"score":8.1,"title":"Reconnection can downgrade connection security settings","url":"https://www.postgresql.org/support/security/CVE-2020-25694/","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Reconnection can downgrade connection security settings","description":"Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission.\n\nAffected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter.\n\nThis also fixes how the \\connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used.\n\nThe PostgreSQL project thanks Peter Eisentraut for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"c57fe2763b8e2dc8a667318f7f400d4428103d23b5da58be49468b23cddaf258"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.15","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"10.15","introduced":null,"published":"2020-11-12"}},{"major":"11","fixed_version":"11.10","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"11.10","introduced":null,"published":"2020-11-12"}},{"major":"12","fixed_version":"12.5","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"12.5","introduced":null,"published":"2020-11-12"}},{"major":"13","fixed_version":"13.1","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"13.1","introduced":null,"published":"2020-11-12"}},{"major":"9.5","fixed_version":"9.5.24","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"9.5.24","introduced":null,"published":"2020-11-12"}},{"major":"9.6","fixed_version":"9.6.20","introduced":null,"published_date":"2020-11-12","facts":{"fixed":"9.6.20","introduced":null,"published":"2020-11-12"}}],"legacy":[]}
